Legal
Privacy Policy
HECKLE is a social accountability app. Friends make pacts, share receipts, and nudge each other. This policy explains what we collect, why we collect it, and how you can delete it.
Information we collect
- Account data — email address, password (stored by Firebase Authentication), display name, handle, avatar emoji/color, and friend code.
- Social content you create — pacts, crew membership, chat/moment messages, reactions, GIF selections, invites, and verification actions.
- Receipt media — photos or screenshots you choose to upload as proof for a pact. We do not access your full photo library; you pick the file.
- Device and notification data — push notification tokens, platform, timezone, and optional lock-screen heckle preferences so we can deliver nudges you enable.
- App settings — notification toggles, GIF autoplay, quiet hours, and friend-permission preferences.
- Diagnostics — basic service logs from Firebase (Auth, Firestore, Functions, Storage, Hosting) needed to run and secure the service. We do not sell personal information and we do not use advertising SDKs in the current app.
How we use information
- Create and secure your account
- Operate pacts, crews, chats, receipts, invites, and friend connections
- Send the push / lock-screen notifications you enable
- Prevent abuse, debug outages, and comply with law
Who can see your information
Profile details and social content are visible to the friends, pact members, or crew members you interact with. Receipt photos are available to members of that pact/crew. Service providers that process data on our behalf include Google Firebase (Authentication, Firestore, Cloud Storage, Cloud Functions, Hosting, and Cloud Messaging) and Expo (push delivery). Optional live GIF search uses KLIPY when that feature is enabled; search queries are sent to KLIPY only when you search.
Data retention
We keep account and social data while your account is active. When you delete your account, we delete or anonymize personal data as described below. Backup systems may retain residual copies for a short period before automatic expiry.
Your choices and account deletion
You can update profile details and notification preferences in the app. You can delete your account:
- In the HECKLE app: You → settings → Delete account
- On the web: heckle-1ddf0.web.app/delete-account
Account deletion removes your Auth account, private profile data, devices, settings, friend code, handle reservation, notifications, and personal receipt media. Shared social history kept for remaining friends is membership-scrubbed or labeled as coming from a deleted user.
Children
HECKLE is not directed to children under 13. Do not create an account if you are under 13. If you believe a child provided personal data, contact us and we will delete it.
Security
We use Firebase Authentication, transport encryption (HTTPS/TLS), and server-side security rules. No method of transmission or storage is perfectly secure.
International processing
HECKLE uses Google Cloud / Firebase infrastructure. Data may be processed in the United States and other regions where those services operate.
Contact
Questions about privacy or deletion: support@lostsheepstudios.com. More help: Support.
Changes
We may update this policy as the product changes. The effective date above will change when we do. Continued use after an update means you accept the revised policy.